You are on page 1of 10

A Method for Combating Random Geometric Attack

on Image Watermarking

I. Wiseto Agung and Peter Sweeney

A method for amending StirMark random geometric attacked watermarked

images is introduced. The proposed scheme uses a reference image to

identify the attacked pixels, then exchanges them for pixels from the

original unwatermarked image. It is shown that the watermark can be

successfully detected after the attacked image is corrected.

Introduction: Many proposed watermarking methods claim their robustness

against common signal processing algorithms and geometric distortions.

However, most of them are not robust against the StirMark distortions

attack, where the image is slightly stretched, sheared, shifted and / or rotated

by unnoticeable random amount then, finally a slight deviation, which is

greatest at the centre of the image, is applied to each pixel. These distortions

do not remove the watermark per se, however, they prevent the detector

from finding it [1].

Several counter attacks have been proposed such as in [2] by unwarping the

distorted image with help of feature points and in [3] by using Delaunay

triangulation. In this letter, we introduce a scheme which is simpler but

effective to amend the random geometric attack.

Proposed Scheme: The basic idea came from a method to test robustness

against cropping, which was described in [4], where cropped parts of the

image are replaced by similar parts from the original image with no

watermarks prior to the detection. Thus, this principle can be applied for

combating StirMark if the attacked parts are known.

A block diagram of the proposed algorithm is shown in Fig.1. The

attacked pixels can be approximated by taking a difference between the

attacked watermarked image (suspect image) and a reference image. Ideally,

the watermarked image containing the same watermark as the suspect image

should be used as the reference image. Nevertheless, in a fingerprinting

application where each recipient has a unique watermark, it is not possible

to identify which watermark was being embedded into the suspect image.

Hence, alternatively, we can use the original image as a reference.

By using this difference, we can determine how many pixels should

be changed. Then, after replacing the attacked pixels by pixels from the

original image, the detection can be completed. It should be noted that there

is a trade off in determining the number of attacked pixels that should be

changed. Changing only few pixels may not reduce the effect of the attack.

On the other hand, replacing too many pixels may reduce the robustness of

the scheme against cropping.

Experimental Results: The spread spectrum watermarking scheme in the

DCT domain suggested by [4] was used to evaluate the effectiveness of the

proposed method. The watermark X is inserted into transform coefficients

of image V to obtain the watermarked image V, by using the following

formula :

vi = vi (1 + xi ) (1)

where is the scaling factor to control the watermark level.

In the detection, the original image is needed to extract the

watermark. Then, similarity between the extracted watermark X* and the

original watermark X is measured by :

X * .X
SIM ( X , X *) = (2)
X * .X *

The simulation was conducted by using Matlab where the

parameters were set as follows. A set of 1000 series of normally distributed

random numbers with mean zero and variance one, where each series

contains 1000 numbers, were provided. Then one series, i.e. # 500, was

selected and used as a watermark, and the greyscale 512 512 Lena image

was used as a host image. The watermark level was set to 0.1. After

embedding the watermark, the StirMark 3.1 random geometric and bending

attack was applied. Then, the proposed method was performed to amend the

watermarked image.

Two different reference images, i.e. watermarked image and original

image, were applied to study the effectiveness of the method. In the case of

the watermarked image as reference, all of the 1000 possible series were

tested. An example of the difference between the suspect image and the

reference image is shown in Fig. 2. White pixels indicate high difference

between the two images or, in other words, they point to the highly distorted

parts. The number of pixels which will be changed can be controlled by

choosing the related difference parameter:

DIFF (u , v) = V R (u , v) V S (u , v) (3)

where V R (u , v) is the intensity of a reference image in pixel (u , v) and

V S (u , v) is the intensity of the suspect image in pixel (u , v) . In the

experiments, several values of DIFF were chosen so that around 20% to

80% of the pixels were replaced.

Table 1 shows the experimental results. It can be seen that with

watermarked images as reference, changing around 30% to 50% of the

attacked pixels will give valid results. The result is categorized to be valid if

the SIM when series #500 is used in the reference, is larger than SIMs when

the other 999 possible references are used. If the original image is used as a

reference, valid results are obtained when 34.3% to 46.1% of the attacked

pixels are changed. Fig.3a and Fig.3b show the detection of the watermark

by using the watermarked image and the original image respectively.

Validity of this method against false positives was assessed by

applying an image with no watermark as a suspect image and the

watermarked images as a reference. The experiments showed that no

watermarks were detected.

Conclusions: A method of amending the random geometric attacked

watermarked image has been presented and the simulations give valid

results. Furthermore, the proposed method can be implemented in both

copyright proving and fingerprinting applications.


1. PETITCOLAS, F.A.P., ANDERSON, R.J., Evaluation of Copyright

Marking Systems, Proceeding of IEEE Multimedia Systems 1999,
vol.1, pp.574-579, 7-11 June 1999, Florence, Italy

2. OZER, I., RAMKUMAR, M., AKANSU, A., A New Method for

Detection of Watermarks in Geometrically Distorted Images,
Proceeding of IEEE International Conference on Accoustic, Speech, and
Signal Processing (ICASSP) 2000, 5-9 June 2000, Istanbul, Turkey

3. DAVOINE, F., Triangular Meshes: A Solution to Resist to Geometric

Distortions Based Watermark-Removal Softwares Proceeding of
European Signal Processing Conference (EUSIPCO) 2000, 5-8
September 2000, Tampere, Finland


Secure Spread Spectrum Watermarking for Multimedia, IEEE
Transactions on Image Processing, vol.6, no.12, December 1997,

Authors affiliations:

I. Wiseto Agung and Peter Sweeney (Centre for Communication System

Research (CCSR), University of Surrey, Guildford GU2 7XH, United

Figure and Table captions:

Fig. 1 Proposed method

Fig. 2 Difference between suspect and original images

Fig. 3 Detection of the watermark by using

(a) watermarked image
(b) original image

Table 1 Detection results for various reference image and DIFF

Figure 1







Figure 2

Figure 3

(a) (b)

Table 1


StirMarked Attacked Watermarked Image > 0.014 71 - 83 invalid
Watermarked Image (watermark #: 1-1000) > 0.040 44 - 53 valid
(watermarked # : 500) > 0.050 39 - 47 valid
> 0.065 33 - 37 valid
> 0.100 24 - 26 invalid
Original Image > 0.010 82.5 invalid
> 0.040 46.1 valid
> 0.050 41.2 valid
> 0.065 34.3 valid
> 0.100 25.1 invalid
Original Image Watermark Image #: 500 > 0.050 0.035 undetected
(no watermark) > 0.010 47.18 undetected
Watermark Image #: 100 > 0.050 0.012 undetected
> 0.010 45.69 undetected